✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 97 to 108 of 5033
CubePilot's DNS Hijacking Incident: A Wake-Up Call for Cybersecurity
In July 2026, CubePilot, an Australian drone software developer, experienced a significant operational disruption due to a DNS hijacking attack. On July 24, attackers gained control over the DNS settings of cubepilot.org, redirecting user traffic to malicious servers. They also obtained TLS certificates for all subdomains, enabling them to intercept sensitive data, including user credentials entered on CubePilot's services. The company promptly regained control, revoked the fraudulent certificates, and initiated an investigation, advising users to change passwords if reused elsewhere. This incident underscores the escalating threat of DNS hijacking attacks targeting critical infrastructure and technology providers. Organizations must enhance their DNS security measures and monitor for unauthorized changes to prevent similar breaches.
4 days ago
Kill Chain
Understanding the 'Certighost' Vulnerability in Microsoft AD CS
In July 2026, Microsoft addressed a critical vulnerability in Active Directory Certificate Services (AD CS), identified as CVE-2026-54121 and nicknamed 'Certighost'. This flaw allowed low-privileged domain users to impersonate domain controllers, potentially leading to full Active Directory domain compromise. The vulnerability exploited a defective trust boundary within the certificate-based client authentication process, enabling attackers to manipulate certificate requests and gain elevated privileges. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/certighost-flaw-microsoft-active-directory-certificates?utm_source=openai)) The release of a proof-of-concept exploit by security researchers has heightened the urgency for organizations to apply the patch. This incident underscores the importance of promptly addressing vulnerabilities in critical infrastructure components to prevent potential domain-wide security breaches. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/07/27/certighost-cve-2026-54121-poc-exploit-released/?utm_source=openai))
4 days ago
Kill Chain
Protecting Against Session Hijacking: Beyond Password Resets
In July 2026, cybersecurity experts highlighted a significant shift in attacker tactics from traditional password theft to session and token hijacking. This method allows adversaries to bypass multi-factor authentication (MFA) by exploiting authenticated sessions, enabling them to impersonate legitimate users and maintain persistent access within trusted environments. Techniques such as device-code phishing and stealing browser cookies have become prevalent, rendering conventional defenses like password resets and MFA prompts less effective. This evolution underscores the urgent need for organizations to move beyond securing initial logins and focus on protecting authenticated sessions throughout their lifecycle. Continuous monitoring of post-authentication behavior, implementing phishing-resistant authentication methods, and promptly revoking compromised tokens are critical measures to mitigate these advanced threats.
4 days ago
Kill Chain
Operation Cronos: A Landmark Takedown of LockBit Ransomware Group
In February 2024, an international law enforcement coalition led by the UK's National Crime Agency (NCA) and the FBI executed Operation Cronos, effectively dismantling the LockBit ransomware group. This operation involved seizing LockBit's infrastructure, including their dark web leak site and administrative panels, arresting key members in Poland and Ukraine, and freezing over 200 cryptocurrency accounts linked to the group. LockBit, active since 2019, was responsible for thousands of ransomware attacks worldwide, extorting over $120 million from victims across various sectors. The takedown significantly disrupted their operations and provided decryption keys to assist victims in data recovery. ([weforum.org](https://www.weforum.org/stories/2024/02/lockbit-ransomware-operation-cronos-cybercrime/?utm_source=openai)) The success of Operation Cronos underscores the effectiveness of coordinated international efforts in combating cybercrime. However, the rapid reemergence of LockBit highlights the resilience of such groups and the ongoing need for vigilance and adaptive cybersecurity strategies to address evolving threats. ([techcrunch.com](https://techcrunch.com/2024/02/26/lockbit-ransomware-takedown-now-what/?utm_source=openai))
4 days ago
Kill Chain
Critical 'Confused Deputy' Vulnerabilities Discovered in Major Cloud Platforms
In May and June 2026, security researcher Justin O'Leary identified 'confused deputy' vulnerabilities in Microsoft Azure and Google Cloud Platform (GCP). These flaws allowed attackers to escalate privileges and bypass access controls. In Azure, the issue involved the Kubernetes Service backup feature, enabling escalation from Backup Contributor to cluster-admin. In GCP, the Config Connector add-on permitted unauthorized users to gain Organization Owner status. Despite disclosures, Microsoft silently patched the flaw, while Google did not acknowledge it as a vulnerability. These incidents underscore the persistent risks in cloud identity management and the need for robust security practices.
4 days ago
Kill Chain
AI Agent Hermes Orchestrates Espionage Attack on Thai Ministry of Finance
In July 2026, Thailand's Ministry of Finance was targeted in a cyber-espionage operation utilizing Hermes, an autonomous open-source AI agent. Operating in 'YOLO mode'—a setting that allows the agent to execute tasks without human approval—the attackers conducted system enumeration, privilege escalation, and network reconnaissance. They accessed sensitive personnel records and internal systems, though no evidence of data exfiltration was found. The attack infrastructure, hosted in Hong Kong, included exploit code for multiple CVEs, web shells, and custom scripts. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/ai-agent-espionage-attack-thai-ministry-finance?utm_source=openai)) This incident underscores the escalating use of AI-driven tools in cyberattacks, highlighting the need for enhanced security measures against autonomous threats. The deployment of AI agents like Hermes in offensive operations signifies a shift in cyber-espionage tactics, necessitating updated defense strategies to mitigate such advanced threats. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/ai-agent-espionage-attack-thai-ministry-finance?utm_source=openai))
4 days ago
Kill Chain
Unveiling 'PleaseFix': The Security Flaws in Agentic Browsers
In July 2026, security researchers identified a class of vulnerabilities, termed 'PleaseFix,' in agentic browsers—AI-powered web browsers designed to automate tasks for users. These vulnerabilities exploit the browsers' relaxed cross-origin policies, allowing attackers to manipulate AI agents into performing unauthorized actions across different web domains. Such exploits can lead to account takeovers, unauthorized transactions, and even remote code execution on the user's system. The fundamental issue lies in the removal of traditional security mechanisms, like the same-origin policy, to enhance AI functionality, thereby exposing users to significant risks. The emergence of 'PleaseFix' vulnerabilities underscores the urgent need for standardized security protocols in AI-integrated browsers. As these browsers gain popularity, the potential for widespread exploitation increases, highlighting the importance of balancing innovation with robust security measures to protect users from evolving cyber threats.
4 days ago
Kill Chain
Arista VeloCloud Orchestrator Vulnerability (CVE-2026-16812) Exploited in the Wild
In July 2026, a critical command injection vulnerability (CVE-2026-16812) was discovered in on-premises versions of Arista VeloCloud Orchestrator (VCO). This flaw allows unauthenticated remote attackers to execute arbitrary commands on the VCO host, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the data it manages. Arista has confirmed active exploitation of this vulnerability in the wild and has released patches to address the issue. Organizations using affected versions are urged to upgrade immediately to mitigate the risk. ([arista.com](https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144?utm_source=openai)) The exploitation of CVE-2026-16812 underscores the increasing targeting of network infrastructure components by threat actors. As SD-WAN solutions like VeloCloud become integral to enterprise networks, ensuring their security is paramount. This incident highlights the necessity for organizations to maintain up-to-date systems and implement robust monitoring to detect and respond to such vulnerabilities promptly.
4 days ago
Kill Chain
AI-Assisted Discovery of CVE-2026-53264: A Linux Kernel Privilege Escalation Vulnerability
In July 2026, STAR Labs disclosed a critical vulnerability in the Linux kernel, identified as CVE-2026-53264, which allows local users to escalate privileges to root. This use-after-free race condition exists in the network traffic-control subsystem and was exploited on CentOS Stream 9. Researcher Lee Jia Jie utilized artificial intelligence to expedite the discovery and development of the exploit. The flaw requires specific kernel configurations and unprivileged user namespaces to be exploitable. The incident underscores the growing role of AI in cybersecurity, both for defense and offense. It highlights the necessity for organizations to promptly apply patches and monitor for emerging threats, especially as exploit code becomes publicly available.
4 days ago
Kill Chain
Nimbus Manticore's 2026 Cyber Campaign: Unveiling NightLedger and Covert Tunneling Techniques
In July 2026, the Iranian state-sponsored hacking group known as Nimbus Manticore (also referred to as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) launched a series of cyber attacks targeting entities across the Middle East, Africa, and South Asia. The group employed a previously undocumented Windows backdoor named NightLedger, along with two custom WebSocket-based tunnelers, BridgeHead and ArcBridge, to maintain covert access to compromised systems. These tools enabled the attackers to perform reconnaissance, execute commands, and establish covert network access, effectively turning victim systems into relay nodes for further malicious activities. This incident underscores the evolving tactics of state-sponsored threat actors, who are increasingly developing and deploying sophisticated malware to achieve persistent access and control over targeted networks. The use of custom tunneling tools and backdoors highlights the need for organizations to enhance their detection and response capabilities to counter such advanced threats.
4 days ago
Kill Chain
Critical TeamCity Vulnerability (CVE-2026-63077) Exposes Servers to Unauthenticated Remote Code Execution
In July 2026, JetBrains identified a critical security vulnerability (CVE-2026-63077) in all versions of TeamCity On-Premises. This flaw allows unauthenticated attackers with HTTP(S) access to bypass authentication and execute arbitrary operating system commands with the privileges of the TeamCity server process. The vulnerability stems from insecure deserialization in the agent polling protocol, enabling remote code execution without credentials or user interaction. JetBrains released patches in versions 2025.11.7 and 2026.1.3 to address this issue. ([blog.jetbrains.com](https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/?utm_source=openai)) The incident underscores the importance of promptly applying security updates to prevent potential exploitation. Organizations using TeamCity On-Premises should upgrade to the patched versions or apply the provided security patch plugin to mitigate the risk of unauthorized access and potential compromise of build environments. ([blog.jetbrains.com](https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/?utm_source=openai))
4 days ago
Kill Chain
Critical Vulnerability in Siemens SIMATIC S7-PLCSIM Advanced: CVE-2026-54429
In July 2026, Siemens disclosed a vulnerability (CVE-2026-54429) in its SIMATIC S7-PLCSIM Advanced software, affecting all versions. The flaw arises from improper handling of high-volume multicast network traffic, leading to memory exhaustion and a denial-of-service condition. An unauthenticated attacker on the local network can exploit this by sending excessive multicast traffic, rendering the application inaccessible until manually restarted. Notably, no project data is lost during this process. Exploitation requires a specific project configuration to be active on the targeted instance. This incident underscores the critical importance of securing industrial control systems against network-based attacks. As industrial environments become increasingly interconnected, vulnerabilities like this highlight the need for robust network segmentation, traffic monitoring, and timely application of security patches to prevent potential disruptions.
4 days ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

